Macao — Cyber Threat Profile
Macao anchors its cyber regime in the Cybersecurity Law (Law No. 13/2019), in force since December 2019, requiring critical infrastructure operators to report incidents to CARIC, the Judiciary Police's 24/7 incident alert and response centre; MOCERT, the territory's FIRST-member CERT, covers community incident response. Exposure centres on the casino economy — gaming taxes supplied about 81% of government revenue in 2024 — which draws espionage interest: the DarkHotel APT spear-phished 17 Macao luxury hotels in late 2021-early 2022. In July 2024 a suspected foreign DDoS took five government security websites offline, and officials report attacks on critical infrastructure more than tripled since 2020. IntelFusions has logged three ransomware leak-site claims against Macao organizations since 2024, two in hospitality and gaming.- National CERT/CSIRT: MOCERT
- Secure Internet servers per 1M people (2024): 6,586.6 (source: World Bank)
- Internet users (2024): 89.8% of population (source: World Bank)
Threat actors targeting Macao
Most targeted sectors
Recent claimed incidents
Read the full analysis on IntelFusions